I have followed the instructions in message #34.
I restarted the machine.
This is the current machine information.
[sc query smtpsvc]
Type : 20 WIN32_SHARE_PROCESS
Condition : 1 STOPPED
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
[sc query schedule]
Type : 20 WIN32_SHARE_PROCESS
Condition : 1 STOPPED
WIN32_EXIT_CODE : 1068 (0x42c)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
[sc query rpcss]
Type : 20 WIN32_SHARE_PROCESS
Condition : 4 RUNNING (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
[sc query DcomLaunch]
Type : 20 WIN32_SHARE_PROCESS
Condition : 4 RUNNING (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
[sc query EventSystem]
Type : 20 WIN32_SHARE_PROCESS
Condition : 4 RUNNING (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
[sc query eventlog]
Type : 20 WIN32_SHARE_PROCESS
Condition : 1 STOPPED
WIN32_EXIT_CODE : 1766 (0x6e6)
SERVICE_EXIT_CODE : 0 (0x0)
Checkpoint : 0x0
WAIT_HINT : 0x0
--------------------------------------
and The owner of the log files (.evtx) in the "C:\Windows\System32\winevt\Logs" folder guess abnormal.
Log files (.evtx) - Properties - Click Security.
It says that you must be a group of administrators to view object properties.